Aggregator
Coremail邮件系统安全风险分析与防护策略、金融机构微服务鉴权机制探讨及公有云出站访问控制方案研究|总第294周
11 months 1 week ago
本期周报简介:1.Coremail如何在关闭SMTP增强安全的同时兼顾客户端发信需求?
2. 金融机构微服务是否需统一网关鉴权,还是按业务线灵活处理?
3. 公有云出站访问如何实现域名及URL级控制,并溯源内网IP?
Daily Dose of Dark Web Informer - 15th of July 2025
11 months 1 week ago
This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X/Twitter posts.
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-42120 | Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8 AMD Display pipe_ctx buffer overflow (Nessus ID 207738 / WID-SEC-2024-1722)
11 months 1 week ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8. This affects the function pipe_ctx of the component AMD Display. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-42120. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42121 | Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8 AMD Display msg_id array index (Nessus ID 207738 / WID-SEC-2024-1722)
11 months 1 week ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8. This affects the function msg_id of the component AMD Display. The manipulation leads to improper validation of array index.
This vulnerability is uniquely identified as CVE-2024-42121. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42116 | Linux Kernel up to 5.15.162/6.1.97/6.6.38/6.9.8 igc_ptp_init uninitialized pointer (WID-SEC-2024-1722)
11 months 1 week ago
A vulnerability was suspected in Linux Kernel up to 5.15.162/6.1.97/6.6.38/6.9.8. Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2024-42118 | Linux Kernel up to 6.9.8 AMD Display array index (a76fa9c4f0fc/3ac31c9a707d / Nessus ID 210060)
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.9.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component AMD Display. The manipulation leads to improper validation of array index.
This vulnerability is known as CVE-2024-42118. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42112 | Linux Kernel up to 6.9.8 txgbe wx_free_isb_resources information disclosure (efdc3f542998/935124dd5883 / Nessus ID 210060)
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.9.8. It has been classified as problematic. Affected is the function wx_free_isb_resources of the component txgbe. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-42112. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Threat Attack Daily - 15th of July 2025
11 months 1 week ago
Threat Attack Daily - 15th of July 2025
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-42114 | Linux Kernel up to 6.9.8 NL80211_ATTR_TXQ_QUANTUM state issue (e87c2f098f52/d1cba2ea8121 / Nessus ID 207773)
11 months 1 week ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.9.8. Affected by this vulnerability is an unknown functionality. The manipulation of the argument NL80211_ATTR_TXQ_QUANTUM leads to state issue.
This vulnerability is known as CVE-2024-42114. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42110 | Linux Kernel up to 6.1.97/6.6.38/6.9.8 ntb_netdev_rx_handler stack-based overflow (Nessus ID 207884 / WID-SEC-2024-1722)
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.1.97/6.6.38/6.9.8 and classified as critical. This issue affects the function ntb_netdev_rx_handler. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-42110. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Ransomware Attack Update for the 15th of July 2025
11 months 1 week ago
Ransomware Attack Update for the 15th of July 2025
Dark Web Informer - Cyber Threat Intelligence
Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others
11 months 1 week ago
Cameron Wagenius faces a maximum of 27 years in prison. A researcher that helped with the investigation called this ‘one of the most significant wins in the fight against cybercrime.'
The post Former Army soldier pleads guilty to widespread attack spree linked to AT&T, Snowflake and others appeared first on CyberScoop.
Matt Kapko
CVE-2024-8984 | berriai litellm up to 1.44.5 HTTP Request resource consumption
11 months 1 week ago
A vulnerability was found in berriai litellm up to 1.44.5. It has been declared as problematic. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to resource consumption.
This vulnerability was named CVE-2024-8984. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-9308 | haotian-liu llava up to 1.2.0 redirect
11 months 1 week ago
A vulnerability has been found in haotian-liu llava up to 1.2.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to open redirect.
This vulnerability was named CVE-2024-9308. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-8613 | gaizhenbiao ChuanhuChatGPT 20240802 access control
11 months 1 week ago
A vulnerability, which was classified as critical, was found in gaizhenbiao ChuanhuChatGPT 20240802. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-8613. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9309 | haotian-liu llava up to 1.2.0/1.6 API Endpoint /worker_generate_stream server-side request forgery
11 months 1 week ago
A vulnerability was found in haotian-liu llava up to 1.2.0/1.6. It has been classified as critical. Affected is an unknown function of the file /worker_generate_stream of the component API Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2024-9309. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8955 | composiohq composio up to 0.4.4 xpath injection
11 months 1 week ago
A vulnerability was found in composiohq composio up to 0.4.4 and classified as problematic. This issue affects the function BROWSERTOOL_GOTO_PAGE/BROWSERTOOL_GET_PAGE_DETAILS. The manipulation leads to improper neutralization of data within xpath expressions.
The identification of this vulnerability is CVE-2024-8955. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-0184 | langgenius dify up to 0.10.x DOCX File ssrf_proxy reltype server-side request forgery
11 months 1 week ago
A vulnerability was found in langgenius dify up to 0.10.x. It has been declared as critical. Affected by this vulnerability is the function ssrf_proxy of the component DOCX File Handler. The manipulation of the argument reltype leads to server-side request forgery.
This vulnerability is known as CVE-2025-0184. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2546 | D-Link DIR-618/DIR-605L 2.02/3.02 Firewall Service /goform/formAdvFirewall access control
11 months 1 week ago
A vulnerability classified as critical was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The manipulation leads to improper access controls. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-2546. The attack needs to be approached within the local network. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com